CVE-2020-5763

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
29/07/2020
Last modified:
31/07/2020

Description

Grandstream HT800 series firmware version 1.0.17.5 and below contain a backdoor in the SSH service. An authenticated remote attacker can obtain a root shell by correctly answering a challenge prompt.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:grandstream:ht801_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht801:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ht802_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht802:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ht812_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht812:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ht814_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht814:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ht818_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht818:-:*:*:*:*:*:*:*
cpe:2.3:o:grandstream:ht813_firmware:*:*:*:*:*:*:*:* 1.0.17.5 (including)
cpe:2.3:h:grandstream:ht813:-:*:*:*:*:*:*:*